Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

1Panel-dev — Vulnerabilities & Security Advisories 79

Browse all 79 CVE security advisories affecting 1Panel-dev. AI-powered Chinese analysis, POCs, and references for each vulnerability.

1Panel-dev is an open-source, modern Linux server management tool designed to simplify the deployment and management of web applications through a graphical interface. Its architecture integrates containerization technologies, allowing users to manage databases, proxies, and monitoring services efficiently. Historically, the platform has been associated with forty-four recorded Common Vulnerabilities and Exposures (CVEs), predominantly involving remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from insufficient input validation in API endpoints or improper access control mechanisms within the web interface. Notable incidents include critical RCE exploits that allowed unauthenticated attackers to gain full system control, highlighting risks inherent in complex management panels. While the project actively patches these issues, the high volume of past CVEs underscores the importance of rigorous security auditing for administrators relying on this tool for critical infrastructure management.

Top products by 1Panel-dev: MaxKB 1Panel CordysCRM KubePi
CVE ID Title CVSS Severity Published
CVE-2026-79919 MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT) — MaxKB CWE-693 6.3 Medium 2026-09-21
CVE-2026-79918 MaxKB: Sandbox escape via unhooked fexecve — MaxKB CWE-693 6.3 Medium 2026-09-21
CVE-2026-77517 MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base — MaxKB CWE-639 5.4 Medium 2026-09-21
CVE-2026-77521 MaxKB: Prompt-injectable agent can lead to command execution — MaxKB CWE-78 10.0 Critical 2026-09-21
CVE-2026-77522 MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind) — MaxKB CWE-918 4.3 Medium 2026-09-21
CVE-2026-79917 MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation — MaxKB CWE-285 6.5 Medium 2026-09-21
CVE-2026-77516 MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path — MaxKB CWE-639 5.4 Medium 2026-09-21
CVE-2026-77523 MaxKB: Cross-workspace model parameter form write — MaxKB CWE-639 7.4 High 2026-09-21
CVE-2026-77525 MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id — MaxKB CWE-862 4.2 Medium 2026-09-21
CVE-2026-77518 MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows — MaxKB CWE-862 5.0 Medium 2026-09-21
CVE-2026-79916 MaxKB AWS Bedrock model credential injection leads to remote code execution — MaxKB CWE-78 9.1 Critical 2026-09-21
CVE-2026-77520 MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application — MaxKB CWE-862 5.4 Medium 2026-09-21
CVE-2026-77519 MaxKB: Expired application API keys remain usable on `/chat/api/mcp` — MaxKB CWE-613 5.4 Medium 2026-09-21
CVE-2026-76899 CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page` — CordysCRM CWE-89 5.7 Medium 2026-09-18
CVE-2026-76902 CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}` — CordysCRM CWE-306 5.0 Medium 2026-09-18
CVE-2026-76900 CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime — CordysCRM CWE-918 6.8 Medium 2026-09-18
CVE-2026-76901 CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and accounts — CordysCRM CWE-639 5.8 Medium 2026-09-18
CVE-2026-63647 CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` — CordysCRM CWE-306 9.3 Critical 2026-09-18
CVE-2026-63646 CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users — CordysCRM CWE-200 6.9 Medium 2026-09-18
CVE-2026-52745 CordysCRM: Customer Public Pool Sorting Field SQL Injection — CordysCRM CWE-89 5.3 Medium 2026-09-18
CVE-2026-65956 KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF — KubePi CWE-306 10.0 Critical 2026-08-26
CVE-2026-69129 KubePi: Insufficient per-cluster authorization checks in cluster management APIs — KubePi CWE-639 5.8 Medium 2026-08-26
CVE-2026-64870 MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation — MaxKB CWE-918 5.3 Medium 2026-07-30
CVE-2026-16223 1Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery — CordysCRM CWE-918 6.3 Medium 2026-07-19
CVE-2026-16222 1Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgery — CordysCRM CWE-918 6.3 Medium 2026-07-19
CVE-2026-54149 MaxKB MCP tool import validation bypass allows post-authentication remote code execution — MaxKB CWE-78 8.8 High 2026-07-10
CVE-2026-56779 MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters — MaxKB CWE-918 6.4 Medium 2026-06-25
CVE-2026-10567 1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting — CordysCRM CWE-79 3.5 Low 2026-06-02
CVE-2026-10514 1Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting — CordysCRM CWE-79 2.4 Low 2026-06-01
CVE-2026-42336 MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch — MaxKB CWE-367 - - 2026-05-26

This page lists every published CVE security advisory associated with 1Panel-dev. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.